CSRF Token Reuse Vulnerability in fiber
CVE-2023-45128

10CRITICAL

Key Information:

Vendor

Gofiber

Status
Vendor
CVE Published:
16 October 2023

What is CVE-2023-45128?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fiber web framework, allowing attackers to execute unauthorized actions on behalf of authenticated users. This security issue arises from inadequate validation of CSRF tokens, enabling attackers to exploit this flaw to inject arbitrary values without requiring authentication. Consequently, it poses a risk to the security and integrity of applications built using Fiber. To mitigate these risks, users should upgrade to version 2.50.0 and implement additional security measures such as captchas, Two-Factor Authentication (2FA), and appropriate session cookie attributes. There are currently no viable workarounds for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

fiber < 2.50.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.